Re: [abfab] Direction Forward for aaa-saml

Leif Johansson <leifj@mnt.se> Wed, 22 July 2015 12:45 UTC

Return-Path: <leifj@mnt.se>
X-Original-To: abfab@ietfa.amsl.com
Delivered-To: abfab@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5A9981A039F for <abfab@ietfa.amsl.com>; Wed, 22 Jul 2015 05:45:47 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.6
X-Spam-Level:
X-Spam-Status: No, score=-2.6 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id PARrjCS3aEdH for <abfab@ietfa.amsl.com>; Wed, 22 Jul 2015 05:45:45 -0700 (PDT)
Received: from mail-wi0-f181.google.com (mail-wi0-f181.google.com [209.85.212.181]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 526D21A1A87 for <abfab@ietf.org>; Wed, 22 Jul 2015 05:44:56 -0700 (PDT)
Received: by wibud3 with SMTP id ud3so152500985wib.1 for <abfab@ietf.org>; Wed, 22 Jul 2015 05:44:55 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:content-type:mime-version:subject:from :in-reply-to:date:cc:content-transfer-encoding:message-id:references :to; bh=uyXwz3blgk8TeNxzKb9d3wxJEFByDsYmXZv/qms/nCo=; b=NR5E9Nc8MlQ9qDqAL+U5afh14+99oH2BDct+Q3y/tmYCakAk8/eTVqkqBUv8W1Md1o VMyEBTc8j5YRtmB9KbeMz2zslUnYgQyzYa3DhTY9JbX7oapGSQfcRAnVrHz+Mn2SBWVh XGXVkKxQdmbk2GVUmAlu4fEZg5LMnyxmuBhTpsIOCZZedCl36yysJ211bzAIe+UyRk1a 7v8GjhfVZpytCeOoYSKuYGwZKtalhKxYMlYK11Cczwx9CJSZXdKL4EI4fK9NU+wQ19lr X/AAxqRtGZE5ispcxhqfcmET+1rIZR3IKWPZOdd4FGfXV/VMjGtl43hHsRj6zkVMJgoj 4y3Q==
X-Gm-Message-State: ALoCoQmJe4JvNPqOnB5rSG9iYwIe2cN40odrLhBQ25MpTnRxD3Q6zcVEjO3bQEvY6Ok0PFoUncNr
X-Received: by 10.180.107.138 with SMTP id hc10mr6291759wib.2.1437569095104; Wed, 22 Jul 2015 05:44:55 -0700 (PDT)
Received: from ?IPv6:2001:67c:370:152:643d:bf30:502d:93c8? ([2001:67c:370:152:643d:bf30:502d:93c8]) by smtp.gmail.com with ESMTPSA id m4sm2233201wjb.37.2015.07.22.05.44.53 (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Wed, 22 Jul 2015 05:44:54 -0700 (PDT)
Content-Type: text/plain; charset=us-ascii
Mime-Version: 1.0 (1.0)
From: Leif Johansson <leifj@mnt.se>
X-Mailer: iPhone Mail (12H143)
In-Reply-To: <tsloaj4xzvr.fsf@mit.edu>
Date: Wed, 22 Jul 2015 14:44:53 +0200
Content-Transfer-Encoding: 7bit
Message-Id: <0B96365A-4F6B-427A-9A87-70F069473F84@mnt.se>
References: <tslwpxsy0ql.fsf@mit.edu> <8E4E5965-0E43-4ABD-8853-8A6C7C6926C5@mnt.se> <tsloaj4xzvr.fsf@mit.edu>
To: Sam Hartman <hartmans@painless-security.com>
Archived-At: <http://mailarchive.ietf.org/arch/msg/abfab/onrarxhZCaLGKsf1KfyMzWHXYTc>
Cc: "abfab@ietf.org" <abfab@ietf.org>
Subject: Re: [abfab] Direction Forward for aaa-saml
X-BeenThere: abfab@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Application Bridging, Federated Authentication Beyond \(the web\)" <abfab.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/abfab>, <mailto:abfab-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/abfab/>
List-Post: <mailto:abfab@ietf.org>
List-Help: <mailto:abfab-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/abfab>, <mailto:abfab-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 22 Jul 2015 12:45:47 -0000


22 jul 2015 kl. 12:14 skrev Sam Hartman <hartmans@painless-security.com>om>:

>>>>>> "Leif" == Leif Johansson <leifj@mnt.se> writes:
> 
>>> 22 jul 2015 kl. 11:56 skrev Sam Hartman
>>> <hartmans@painless-security.com>om>:
>>> 
>>> In the meeting we discussed that we really aren't specifying an
>>> edpoint.  In particular, the location of the service is implicit
>>> in this RADIUS binding.  It's possible we might describe
>>> something in the future where we included radsec endpoints and
>>> keys in metadata, but that's not what we need now.
> 
>    Leif> agree but it may be cheap/easy to include that upfront
> 
> Doing the metadata specification would be cheap/easy.
> Describing semantics would I suspect be more difficult.

maybe... but lets think about it/try 

> We'd have to treat RADIUS as much less of a black box than we've done so
> far.